<!DOCTYPE html><html lang="zh-CN" data-theme="light"><head><meta charset="UTF-8"><meta http-equiv="X-UA-Compatible" content="IE=edge"><meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no"><title>2022年Hack the box:Tier1免费区全解 | Mox的笔记库</title><meta name="keywords" content="Working"><meta name="author" content="MocusEZ"><meta name="copyright" content="MocusEZ"><meta name="format-detection" content="telephone=no"><meta name="theme-color" content="#ffffff"><meta name="description" content="准备考CISP-PTE了，顺带把之前HTB没刷完的starting point一并刷完">
<meta property="og:type" content="article">
<meta property="og:title" content="2022年Hack the box:Tier1免费区全解">
<meta property="og:url" content="https://www.mocusez.site/posts/2c2e.html">
<meta property="og:site_name" content="Mox的笔记库">
<meta property="og:description" content="准备考CISP-PTE了，顺带把之前HTB没刷完的starting point一并刷完">
<meta property="og:locale" content="zh_CN">
<meta property="og:image" content="https://tse2-mm.cn.bing.net/th/id/OIP-C.FOiYj3Tyj3Bd4IDouzW23wHaDI?pid=ImgDet&rs=1">
<meta property="article:published_time" content="2022-09-27T03:26:26.000Z">
<meta property="article:modified_time" content="2022-09-27T03:26:26.000Z">
<meta property="article:author" content="MocusEZ">
<meta property="article:tag" content="Working">
<meta name="twitter:card" content="summary">
<meta name="twitter:image" content="https://tse2-mm.cn.bing.net/th/id/OIP-C.FOiYj3Tyj3Bd4IDouzW23wHaDI?pid=ImgDet&rs=1"><link rel="shortcut icon" href="/img/title.jpg"><link rel="canonical" href="https://www.mocusez.site/posts/2c2e"><link rel="preconnect" href="//cdn.jsdelivr.net"/><link rel="preconnect" href="//hm.baidu.com"/><link rel="preconnect" href="//busuanzi.ibruce.info"/><link rel="stylesheet" href="/css/index.css"><link rel="stylesheet" href="https://cdn.jsdelivr.net/npm/@fortawesome/fontawesome-free/css/all.min.css" media="print" onload="this.media='all'"><link rel="stylesheet" href="https://cdn.jsdelivr.net/npm/@fancyapps/ui/dist/fancybox.min.css" media="print" onload="this.media='all'"><script>var _hmt = _hmt || [];
(function() {
  var hm = document.createElement("script");
  hm.src = "https://hm.baidu.com/hm.js?c85c9eaebc158345532b86397a6dded9";
  var s = document.getElementsByTagName("script")[0]; 
  s.parentNode.insertBefore(hm, s);
})();
</script><script>const GLOBAL_CONFIG = { 
  root: '/',
  algolia: undefined,
  localSearch: {"path":"/search.xml","preload":false,"languages":{"hits_empty":"找不到您查询的内容：${query}"}},
  translate: undefined,
  noticeOutdate: undefined,
  highlight: {"plugin":"highlighjs","highlightCopy":true,"highlightLang":true,"highlightHeightLimit":false},
  copy: {
    success: '复制成功',
    error: '复制错误',
    noSupport: '浏览器不支持'
  },
  relativeDate: {
    homepage: false,
    post: false
  },
  runtime: '天',
  date_suffix: {
    just: '刚刚',
    min: '分钟前',
    hour: '小时前',
    day: '天前',
    month: '个月前'
  },
  copyright: undefined,
  lightbox: 'fancybox',
  Snackbar: undefined,
  source: {
    justifiedGallery: {
      js: 'https://cdn.jsdelivr.net/npm/flickr-justified-gallery/dist/fjGallery.min.js',
      css: 'https://cdn.jsdelivr.net/npm/flickr-justified-gallery/dist/fjGallery.min.css'
    }
  },
  isPhotoFigcaption: false,
  islazyload: false,
  isAnchor: false
}</script><script id="config-diff">var GLOBAL_CONFIG_SITE = {
  title: '2022年Hack the box:Tier1免费区全解',
  isPost: true,
  isHome: false,
  isHighlightShrink: false,
  isToc: true,
  postUpdate: '2022-09-27 11:26:26'
}</script><noscript><style type="text/css">
  #nav {
    opacity: 1
  }
  .justified-gallery img {
    opacity: 1
  }

  #recent-posts time,
  #post-meta time {
    display: inline !important
  }
</style></noscript><script>(win=>{
    win.saveToLocal = {
      set: function setWithExpiry(key, value, ttl) {
        if (ttl === 0) return
        const now = new Date()
        const expiryDay = ttl * 86400000
        const item = {
          value: value,
          expiry: now.getTime() + expiryDay,
        }
        localStorage.setItem(key, JSON.stringify(item))
      },

      get: function getWithExpiry(key) {
        const itemStr = localStorage.getItem(key)

        if (!itemStr) {
          return undefined
        }
        const item = JSON.parse(itemStr)
        const now = new Date()

        if (now.getTime() > item.expiry) {
          localStorage.removeItem(key)
          return undefined
        }
        return item.value
      }
    }
  
    win.getScript = url => new Promise((resolve, reject) => {
      const script = document.createElement('script')
      script.src = url
      script.async = true
      script.onerror = reject
      script.onload = script.onreadystatechange = function() {
        const loadState = this.readyState
        if (loadState && loadState !== 'loaded' && loadState !== 'complete') return
        script.onload = script.onreadystatechange = null
        resolve()
      }
      document.head.appendChild(script)
    })
  
      win.activateDarkMode = function () {
        document.documentElement.setAttribute('data-theme', 'dark')
        if (document.querySelector('meta[name="theme-color"]') !== null) {
          document.querySelector('meta[name="theme-color"]').setAttribute('content', '#0d0d0d')
        }
      }
      win.activateLightMode = function () {
        document.documentElement.setAttribute('data-theme', 'light')
        if (document.querySelector('meta[name="theme-color"]') !== null) {
          document.querySelector('meta[name="theme-color"]').setAttribute('content', '#ffffff')
        }
      }
      const t = saveToLocal.get('theme')
    
          if (t === 'dark') activateDarkMode()
          else if (t === 'light') activateLightMode()
        
      const asideStatus = saveToLocal.get('aside-status')
      if (asideStatus !== undefined) {
        if (asideStatus === 'hide') {
          document.documentElement.classList.add('hide-aside')
        } else {
          document.documentElement.classList.remove('hide-aside')
        }
      }
    
    const detectApple = () => {
      if(/iPad|iPhone|iPod|Macintosh/.test(navigator.userAgent)){
        document.documentElement.classList.add('apple')
      }
    }
    detectApple()
    })(window)</script><meta name="generator" content="Hexo 6.2.0"><link rel="alternate" href="/atom.xml" title="Mox的笔记库" type="application/atom+xml">
</head><body><div id="sidebar"><div id="menu-mask"></div><div id="sidebar-menus"><div class="avatar-img is-center"><img src="/img/head.jpg" onerror="onerror=null;src='/img/friend_404.gif'" alt="avatar"/></div><div class="sidebar-site-data site-data is-center"><a href="/archives/"><div class="headline">文章</div><div class="length-num">61</div></a><a href="/tags/"><div class="headline">标签</div><div class="length-num">0</div></a><a href="/categories/"><div class="headline">分类</div><div class="length-num">8</div></a></div><hr/><div class="menus_items"><div class="menus_item"><a class="site-page" href="/"><i class="fa-fw fas fa-home"></i><span> 首页</span></a></div><div class="menus_item"><a class="site-page" href="/archives/"><i class="fa-fw fas fa-archive"></i><span> 归档</span></a></div><div class="menus_item"><a class="site-page" href="/categories/"><i class="fa-fw fas fa-folder-open"></i><span> 分类</span></a></div><div class="menus_item"><a class="site-page" href="/link/"><i class="fa-fw fas fa-link"></i><span> 友链&amp;私人收藏</span></a></div><div class="menus_item"><a class="site-page" href="/board/"><i class="fa-fw fas fa-user"></i><span> 留言板</span></a></div></div></div></div><div class="post" id="body-wrap"><header class="post-bg" id="page-header" style="background-image: url('https://tse2-mm.cn.bing.net/th/id/OIP-C.FOiYj3Tyj3Bd4IDouzW23wHaDI?pid=ImgDet&amp;rs=1')"><nav id="nav"><span id="blog_name"><a id="site-name" href="/">Mox的笔记库</a></span><div id="menus"><div id="search-button"><a class="site-page social-icon search"><i class="fas fa-search fa-fw"></i><span> 搜索</span></a></div><div class="menus_items"><div class="menus_item"><a class="site-page" href="/"><i class="fa-fw fas fa-home"></i><span> 首页</span></a></div><div class="menus_item"><a class="site-page" href="/archives/"><i class="fa-fw fas fa-archive"></i><span> 归档</span></a></div><div class="menus_item"><a class="site-page" href="/categories/"><i class="fa-fw fas fa-folder-open"></i><span> 分类</span></a></div><div class="menus_item"><a class="site-page" href="/link/"><i class="fa-fw fas fa-link"></i><span> 友链&amp;私人收藏</span></a></div><div class="menus_item"><a class="site-page" href="/board/"><i class="fa-fw fas fa-user"></i><span> 留言板</span></a></div></div><div id="toggle-menu"><a class="site-page"><i class="fas fa-bars fa-fw"></i></a></div></div></nav><div id="post-info"><h1 class="post-title">2022年Hack the box:Tier1免费区全解</h1><div id="post-meta"><div class="meta-firstline"><span class="post-meta-date"><i class="far fa-calendar-alt fa-fw post-meta-icon"></i><span class="post-meta-label">发表于</span><time class="post-meta-date-created" datetime="2022-09-27T03:26:26.000Z" title="发表于 2022-09-27 11:26:26">2022-09-27</time><span class="post-meta-separator">|</span><i class="fas fa-history fa-fw post-meta-icon"></i><span class="post-meta-label">更新于</span><time class="post-meta-date-updated" datetime="2022-09-27T03:26:26.000Z" title="更新于 2022-09-27 11:26:26">2022-09-27</time></span><span class="post-meta-categories"><span class="post-meta-separator">|</span><i class="fas fa-inbox fa-fw post-meta-icon"></i><a class="post-meta-categories" href="/categories/%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95%E7%AC%94%E8%AE%B0/">渗透测试笔记</a></span></div><div class="meta-secondline"><span class="post-meta-separator">|</span><span class="post-meta-pv-cv" id="" data-flag-title="2022年Hack the box:Tier1免费区全解"><i class="far fa-eye fa-fw post-meta-icon"></i><span class="post-meta-label">阅读量:</span><span id="busuanzi_value_page_pv"><i class="fa-solid fa-spinner fa-spin"></i></span></span></div></div></div></header><main class="layout" id="content-inner"><div id="post"><article class="post-content" id="article-container"><p>准备考CISP-PTE了，顺带把之前HTB没刷完的starting point一并刷完</p>
<h2 id="Appointment"><a href="#Appointment" class="headerlink" title="Appointment"></a>Appointment</h2><p>上来先扫一下，80进入</p>
<p><img src="https://pic1.58cdn.com.cn/nowater/webim/big/n_v2a606491013eb41dcbcbe96d61caf4b9c.png" alt="image-20220924142527639.png"></p>
<p>1.What does the acronym SQL stand for?</p>
<p>Structured Query Language</p>
<p>2.What is one of the most common type of SQL vulnerabilities?</p>
<p>sql injection</p>
<p>3.What does PII stand for?</p>
<p>Personally identifiable information</p>
<p>没听说过</p>
<p>4.What does the OWASP Top 10 list name the classification for this vulnerability?</p>
<p>A03:2021-Injection</p>
<p>5.What service and version are running on port 80 of the target?</p>
<p>Apache httpd 2.4.38 ((Debian))</p>
<p>6.What is the standard port used for the HTTPS protocol?</p>
<p>443</p>
<p>7.What is one luck-based method of exploiting login pages?</p>
<p>brute-forcing</p>
<p>这个答案就很让人无语，但细想一下，确实是lucky base</p>
<p>8.What is a folder called in web-application terminology?</p>
<p>directory</p>
<p>不懂了 directory不就是folder嘛</p>
<p>9.What response code is given for “Not Found” errors?</p>
<p>404</p>
<p>10.What switch do we use with Gobuster to specify we’re looking to discover directories, and not subdomains?</p>
<p>dir</p>
<p>11.What symbol do we use to comment out parts of the code?</p>
<figure class="highlight plaintext"><table><tr><td class="gutter"><pre><span class="line">1</span><br></pre></td><td class="code"><pre><span class="line">#</span><br></pre></td></tr></table></figure>

<p>登陆那一栏，登入名存在sql注入，密码随便填</p>
<figure class="highlight plaintext"><table><tr><td class="gutter"><pre><span class="line">1</span><br></pre></td><td class="code"><pre><span class="line">admin ‘#</span><br></pre></td></tr></table></figure>

<p>flag{e3d0796d002a446c0e622226f42e9672}</p>
<h2 id="Sequel"><a href="#Sequel" class="headerlink" title="Sequel"></a>Sequel</h2><p>1.What does the acronym SQL stand for?</p>
<p>首字母缩写词 SQL 代表什么？</p>
<p>答案：Structured Query Language</p>
<p>2.During our scan, which port running mysql do we find?</p>
<p>在我们的扫描过程中，我们找到了哪个运行 mysql 的端口？</p>
<p>答案：3306</p>
<p>TASK 3</p>
<p>What community-developed MySQL version is the target running?</p>
<p>目标运行的是哪个社区开发的 MySQL 版本？</p>
<p>答案：MariaDB</p>
<p>TASK 4</p>
<p>What switch do we need to use in order to specify a login username for the MySQL service?</p>
<p>我们需要使用什么命令来指定 MySQL 服务的登录用户名？</p>
<p>答案：-u</p>
<p>TASK 5</p>
<p>Which username allows us to log into MariaDB without providing a password?</p>
<p>哪个用户名允许我们在不提供密码的情况下登录 MariaDB？</p>
<p>答案：root</p>
<p>TASK 6</p>
<p>What symbol can we use to specify within the query that we want to display eveything inside a table?</p>
<p>我们可以使用什么符号在查询中指定要在表中显示所有内容？</p>
<p>答案：*</p>
<p>TASK 7</p>
<p>What symbol do we need to end each query with?</p>
<p>我们需要用什么符号来结束每个查询？</p>
<p>答案：;</p>
<p>数据库连上：</p>
<figure class="highlight plaintext"><table><tr><td class="gutter"><pre><span class="line">1</span><br></pre></td><td class="code"><pre><span class="line">mysql -h 10.129.131.87 -u root -P 3306</span><br></pre></td></tr></table></figure>

<p>sql语句用的不太熟，还是把笔记翻出来才想起来的</p>
<p><img src="https://pic4.58cdn.com.cn/nowater/webim/big/n_v2c9d9c08c00e74af08360b08ec66b479a.png" alt="image-20220924145411836.png"></p>
<p>flag{7b4bec00d1a39e3dd4e021ec3d915da8}</p>
<h2 id="Crocodile"><a href="#Crocodile" class="headerlink" title="Crocodile"></a>Crocodile</h2><p>照例先扫端口</p>
<p><img src="https://pic7.58cdn.com.cn/nowater/webim/big/n_v2a8fc9fe00cba4f7f8097507679434000.png" alt="image-20220924151202049.png"></p>
<p>TASK 1</p>
<p>What nmap scanning switch employs the use of default scripts during a scan?</p>
<p>什么 nmap 扫描开关在扫描期间使用默认脚本？</p>
<p>答案：-sC</p>
<p>TASK 2</p>
<p>What service version is found to be running on port 21?</p>
<p>发现什么服务版本在端口 21 上运行？</p>
<p>答案：vsftpd 3.0.3</p>
<p>TASK 3</p>
<p>What FTP code is returned to us for the “Anonymous FTP login allowed” message?</p>
<p>“允许匿名 FTP 登录”消息返回给我们的 FTP 代码是什么？</p>
<p>答案：230</p>
<p>TASK 4</p>
<p>What command can we use to download the files we find on the FTP server?</p>
<p>我们可以使用什么命令来下载我们在 FTP 服务器上找到的文件？</p>
<p>答案：get</p>
<p>TASK 5</p>
<p>What is one of the higher-privilege sounding usernames in the list we retrieved?</p>
<p>我们检索到的列表中听起来更高权限的用户名之一是什么？</p>
<p>答案：admin</p>
<p>TASK 6</p>
<p>What version of Apache HTTP Server is running on the target host?</p>
<p>目标主机上运行的是什么版本的 Apache HTTP Server？</p>
<p>答案：2.4.41</p>
<p>TASK 7</p>
<p>What is the name of a handy web site analysis plug-in we can install in our browser?</p>
<p>我们可以在浏览器中安装的方便的网站分析插件的名称是什么？</p>
<p>答案：wappalyzer</p>
<p>TASK 8</p>
<p>What switch can we use with gobuster to specify we are looking for specific filetypes?</p>
<p>我们可以在 gobuster 中使用什么开关来指定我们正在寻找特定的文件类型？</p>
<p>答案：-x</p>
<p>TASK 9</p>
<p>What file have we found that can provide us a foothold on the target?</p>
<p>我们发现了哪些文件可以为我们在目标上提供立足点？</p>
<p>答案：login.php</p>
<p>从22端口上去，拿下admin用户名与密码，用御剑扫出login.php,从login.php登入就可以拿下这道题</p>
<p><img src="https://pic2.58cdn.com.cn/nowater/webim/big/n_v2813a40c92caf4f7d9c8eff4776118068.png" alt="image-20220924150840745.png"></p>
<p><img src="https://pic6.58cdn.com.cn/nowater/webim/big/n_v26e6a53bb33f94d699d4537f6d71f91ad.png" alt="image-20220924151303474.png"></p>
<h2 id="Responder"><a href="#Responder" class="headerlink" title="Responder"></a>Responder</h2><p><img src="https://pic3.58cdn.com.cn/nowater/webim/big/n_v274a5a85950f6477296db81d58f8e3d44.png" alt="image-20220924151858227.png"></p>
<p>1.When visiting the web service using the IP address, what is the domain that we are being redirected to?</p>
<p>直接访问IP，会跳转unika.htb</p>
<p><img src="https://pic1.58cdn.com.cn/nowater/webim/big/n_v2a3d968d0332643a292712b75ee3c66b3.png" alt="image-20220924152033875.png"></p>
<p>时候就要绑定host</p>
<p>2.Which scripting language is being used on the server to generate webpages?</p>
<p>php</p>
<p><img src="https://pic2.58cdn.com.cn/nowater/webim/big/n_v24ad0818fd6c94237aff7729b7ffe5159.png" alt="image-20220924152412397.png"><br>3.What is the name of the URL parameter which is used to load different language versions of the webpage?</p>
<p>page</p>
<p>4.Which of the following values for the <code>page</code> parameter would be an example of exploiting a Local File Include (LFI) vulnerability: “french.html”, “&#x2F;&#x2F;10.10.14.6&#x2F;somefile”, “..&#x2F;..&#x2F;..&#x2F;..&#x2F;..&#x2F;..&#x2F;..&#x2F;..&#x2F;windows&#x2F;system32&#x2F;drivers&#x2F;etc&#x2F;hosts”, “minikatz.exe”</p>
<p>问本地文件包含</p>
<p>当然是 ..&#x2F;..&#x2F;..&#x2F;..&#x2F;..&#x2F;..&#x2F;..&#x2F;..&#x2F;windows&#x2F;system32&#x2F;drivers&#x2F;etc&#x2F;hosts</p>
<p>5.Which of the following values for the <code>page</code> parameter would be an example of exploiting a Remote File Include (RFI) vulnerability: “french.html”, “&#x2F;&#x2F;10.10.14.6&#x2F;somefile”, “..&#x2F;..&#x2F;..&#x2F;..&#x2F;..&#x2F;..&#x2F;..&#x2F;..&#x2F;windows&#x2F;system32&#x2F;drivers&#x2F;etc&#x2F;hosts”, “minikatz.exe”</p>
<p>文件远程包含</p>
<p>&#x2F;&#x2F;10.10.14.6&#x2F;somefile</p>
<ol start="6">
<li>What does NTLM stand for?</li>
</ol>
<p>New Technology Lan Manager</p>
<ol start="7">
<li><p>Which flag do we use in the Responder utility to specify the network interface?</p>
<p>-I</p>
</li>
</ol>
<p>responder是用于smb攻击的软件，浏览器通过page远程包含，访问我们tun0网卡，就可以拿到可以被用来爆破的hash</p>
<figure class="highlight plaintext"><table><tr><td class="gutter"><pre><span class="line">1</span><br></pre></td><td class="code"><pre><span class="line">sudo responder -I tun0 </span><br></pre></td></tr></table></figure>

<p><img src="https://pic1.58cdn.com.cn/nowater/webim/big/n_v2e6a5ea4f38af4c53b5fcc03937c4b6ce.png" alt="image-20220924203504364.png"></p>
<ol start="8">
<li><p>There are several tools that take a NetNTLMv2 challenge&#x2F;response and try millions of passwords to see if any of them generate the same response. One such tool is often referred to as <code>john</code>, but the full name is what?.</p>
<p>John the Ripper</p>
</li>
<li><p>What is the password for the administrator user?</p>
<p>badminton</p>
</li>
<li><p>We’ll use a Windows service (i.e. running on the box) to remotely access the Responder machine using the password we recovered. What port TCP does it listen on?</p>
<p>开始居然没有扫出来，只能假装不知道，再手动扫一下</p>
</li>
</ol>
<p><img src="https://pic6.58cdn.com.cn/nowater/webim/big/n_v24efb5796423b48448427cbfb0ece7e64.png" alt="image-20220924154414661.png"></p>
<p>注意，flag不在adminstartor，而是在Mike下面，进去之后记得手动切换</p>
<p><img src="https://pic4.58cdn.com.cn/nowater/webim/big/n_v2967c5efdd6e343049716724f6199cd95.png" alt="image-20220924202439494.png"></p>
<h2 id="Three"><a href="#Three" class="headerlink" title="Three"></a>Three</h2><p><img src="https://pic2.58cdn.com.cn/nowater/webim/big/n_v22bead7ed8862449c8530c7585bb762f8.png" alt="image-20220924191314850.png"></p>
<ol>
<li><p>How many TCP ports are open?</p>
<p>2</p>
</li>
<li><p>What is the domain of the email address provided in the “Contact” section of the website?<br> <a href="mailto:&#x6d;&#x61;&#x69;&#x6c;&#x40;&#116;&#x68;&#101;&#116;&#x6f;&#x70;&#x70;&#101;&#114;&#x73;&#x2e;&#x68;&#x74;&#x62;" rel="external nofollow noreferrer">&#x6d;&#x61;&#x69;&#x6c;&#x40;&#116;&#x68;&#101;&#116;&#x6f;&#x70;&#x70;&#101;&#114;&#x73;&#x2e;&#x68;&#x74;&#x62;</a></p>
</li>
</ol>
<p><img src="https://pic7.58cdn.com.cn/nowater/webim/big/n_v20f66ab83c2094c6bb81dc9d3c8031c53.png" alt="image-20220924191342457.png"></p>
<ol start="3">
<li><p>In the absence of a DNS server, which Linux file can we use to resolve hostnames to IP addresses in order to be able to access the websites that point to those hostnames?<br> &#x2F;etc&#x2F;hosts</p>
</li>
<li><p>Which sub-domain is discovered during further enumeration?</p>
<p>用御剑或gobuster爆破，得到s3</p>
</li>
</ol>
<p>5.Which service is running on the discovered sub-domain?<br>amazon s3</p>
<p><img src="https://pic1.58cdn.com.cn/nowater/webim/big/n_v2a83ada1e210248c9971667b605739b4c.png" alt="image-20220924193733046.png"></p>
<p>6.Which command line utility can be used to interact with the service running on the discovered sub-domain?<br>awscli</p>
<p>7.Which command is used to set up the AWS CLI installation?<br>aws configure</p>
<p>8.What is the command used by the above utility to list all of the S3 buckets?</p>
<figure class="highlight plaintext"><table><tr><td class="gutter"><pre><span class="line">1</span><br></pre></td><td class="code"><pre><span class="line">aws s3 ls</span><br></pre></td></tr></table></figure>
<p>9.This server is configured to run files written in what web scripting language?<br>php</p>
<p>使用aws configure里面所有内容填qwe就能过</p>
<p><img src="https://pic2.58cdn.com.cn/nowater/webim/big/n_v22f9b609342e147f4b3812b61e6fab4ca.png" alt="image-20220924194314756.png"></p>
<figure class="highlight plaintext"><table><tr><td class="gutter"><pre><span class="line">1</span><br></pre></td><td class="code"><pre><span class="line">aws s3 --endpoint=http://s3.thetoppers.htb ls s3://thetoppers.htb</span><br></pre></td></tr></table></figure>

<p>把写好的马传上去</p>
<figure class="highlight plaintext"><table><tr><td class="gutter"><pre><span class="line">1</span><br></pre></td><td class="code"><pre><span class="line">aws --endpoint=http://s3.thetoppers.htb s3 cp shell.php s3://thetoppers.htb</span><br></pre></td></tr></table></figure>

<p><img src="https://pic6.58cdn.com.cn/nowater/webim/big/n_v236354476c198475e887863a9abab930e.png" alt="image-20220924195134773.png"></p>
<p>蚁剑连上去，美滋滋</p>
<p><img src="https://pic6.58cdn.com.cn/nowater/webim/big/n_v21d29ed903e814b8f926d186ad6d52f9e.png" alt="image-20220924195245105.png"></p>
<p>flag就在上一层</p>
<p><img src="https://pic2.58cdn.com.cn/nowater/webim/big/n_v2b586c3b555284c43b34c4959d8185b21.png" alt="image-20220924195346838.png"></p>
</article><div class="post-copyright"><div class="post-copyright__author"><span class="post-copyright-meta">文章作者: </span><span class="post-copyright-info"><a href="https://www.mocusez.site">MocusEZ</a></span></div><div class="post-copyright__type"><span class="post-copyright-meta">文章链接: </span><span class="post-copyright-info"><a href="https://www.mocusez.site/posts/2c2e.html">https://www.mocusez.site/posts/2c2e.html</a></span></div><div class="post-copyright__notice"><span class="post-copyright-meta">版权声明: </span><span class="post-copyright-info">本博客所有文章除特别声明外，均采用 <a href="https://creativecommons.org/licenses/by-nc/4.0" rel="external nofollow noreferrer" target="_blank">CC BY-NC 4.0</a> 许可协议。转载请注明来自 <a href="https://www.mocusez.site" target="_blank">Mox的笔记库</a>！</span></div></div><div class="tag_share"><div class="post-meta__tag-list"></div><div class="post_share"><div class="social-share" data-image="https://tse2-mm.cn.bing.net/th/id/OIP-C.FOiYj3Tyj3Bd4IDouzW23wHaDI?pid=ImgDet&amp;rs=1" data-sites="facebook,twitter,wechat,weibo,qq"></div><link rel="stylesheet" href="https://cdn.jsdelivr.net/npm/butterfly-extsrc/sharejs/dist/css/share.min.css" media="print" onload="this.media='all'"><script src="https://cdn.jsdelivr.net/npm/butterfly-extsrc/sharejs/dist/js/social-share.min.js" defer></script></div></div><nav class="pagination-post" id="pagination"><div class="prev-post pull-left"><a href="/posts/ffd4.html"><img class="prev-cover" src="https://picx.zhimg.com/80/v2-11300de439ef479fbba4757254557bb5_720w.webp" onerror="onerror=null;src='/img/404.jpg'" alt="cover of previous post"><div class="pagination-info"><div class="label">上一篇</div><div class="prev_info">202202，困惑，混乱与未曾设想之路</div></div></a></div><div class="next-post pull-right"><a href="/posts/c87a.html"><img class="next-cover" src="https://dd-static.jd.com/ddimg/jfs/t1/25609/34/18649/514869/631a048dE626216a2/deba1d9c4705b6de.png" onerror="onerror=null;src='/img/404.jpg'" alt="cover of next post"><div class="pagination-info"><div class="label">下一篇</div><div class="next_info">Navidrome部署记录</div></div></a></div></nav><hr/><div id="post-comment"><div class="comment-head"><div class="comment-headline"><i class="fas fa-comments fa-fw"></i><span> 评论</span></div></div><div class="comment-wrap"><div><div id="waline-wrap"></div></div></div></div></div><div class="aside-content" id="aside-content"><div class="card-widget card-info"><div class="is-center"><div class="avatar-img"><img src="/img/head.jpg" onerror="this.onerror=null;this.src='/img/friend_404.gif'" alt="avatar"/></div><div class="author-info__name">MocusEZ</div><div class="author-info__description">探索未曾设想的道路</div></div><div class="card-info-data site-data is-center"><a href="/archives/"><div class="headline">文章</div><div class="length-num">61</div></a><a href="/tags/"><div class="headline">标签</div><div class="length-num">0</div></a><a href="/categories/"><div class="headline">分类</div><div class="length-num">8</div></a></div><div class="card-info-social-icons is-center"><a class="social-icon" href="https://github.com/mocusez" rel="external nofollow noreferrer" target="_blank" title="Github"><i class="fab fa-github"></i></a><a class="social-icon" href="mailto:285918468@qq.com" rel="external nofollow noreferrer" target="_blank" title="Email"><i class="fas fa-envelope"></i></a><a class="social-icon" href="/atom.xml" target="_blank" title="RSS"><i class="fas fa-rss"></i></a></div></div><div class="card-widget card-announcement"><div class="item-headline"><i class="fas fa-bullhorn fa-shake"></i><span>公告</span></div><div class="announcement_content">迎接新的明天</div></div><div class="sticky_layout"><div class="card-widget" id="card-toc"><div class="item-headline"><i class="fas fa-stream"></i><span>目录</span><span class="toc-percentage"></span></div><div class="toc-content"><ol class="toc"><li class="toc-item toc-level-2"><a class="toc-link" href="#Appointment"><span class="toc-number">1.</span> <span class="toc-text">Appointment</span></a></li><li class="toc-item toc-level-2"><a class="toc-link" href="#Sequel"><span class="toc-number">2.</span> <span class="toc-text">Sequel</span></a></li><li class="toc-item toc-level-2"><a class="toc-link" href="#Crocodile"><span class="toc-number">3.</span> <span class="toc-text">Crocodile</span></a></li><li class="toc-item toc-level-2"><a class="toc-link" href="#Responder"><span class="toc-number">4.</span> <span class="toc-text">Responder</span></a></li><li class="toc-item toc-level-2"><a class="toc-link" href="#Three"><span class="toc-number">5.</span> <span class="toc-text">Three</span></a></li></ol></div></div><div class="card-widget card-recent-post"><div class="item-headline"><i class="fas fa-history"></i><span>最新文章</span></div><div class="aside-list"><div class="aside-list-item"><a class="thumbnail" href="/posts/3e9f.html" title="RMM观察与初探"><img src="https://z1.ax1x.com/2023/10/21/piF47TA.md.png" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="RMM观察与初探"/></a><div class="content"><a class="title" href="/posts/3e9f.html" title="RMM观察与初探">RMM观察与初探</a><time datetime="2023-10-21T04:30:00.000Z" title="发表于 2023-10-21 12:30:00">2023-10-21</time></div></div><div class="aside-list-item"><a class="thumbnail" href="/posts/5e44.html" title="计算机网络课设——UDP/TCP/TLS Socket实验"><img src="https://s1.ax1x.com/2023/09/09/pP6qXOU.png" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="计算机网络课设——UDP/TCP/TLS Socket实验"/></a><div class="content"><a class="title" href="/posts/5e44.html" title="计算机网络课设——UDP/TCP/TLS Socket实验">计算机网络课设——UDP/TCP/TLS Socket实验</a><time datetime="2023-09-09T07:10:00.000Z" title="发表于 2023-09-09 15:10:00">2023-09-09</time></div></div><div class="aside-list-item"><a class="thumbnail" href="/posts/cd44.html" title="JQuery的XSS初探"><img src="https://s1.ax1x.com/2023/09/08/pPyvO0O.jpg" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="JQuery的XSS初探"/></a><div class="content"><a class="title" href="/posts/cd44.html" title="JQuery的XSS初探">JQuery的XSS初探</a><time datetime="2023-09-08T04:30:00.000Z" title="发表于 2023-09-08 12:30:00">2023-09-08</time></div></div><div class="aside-list-item"><a class="thumbnail" href="/posts/5862.html" title="生产实习记录"><img src="https://s1.ax1x.com/2023/09/02/pPBH058.png" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="生产实习记录"/></a><div class="content"><a class="title" href="/posts/5862.html" title="生产实习记录">生产实习记录</a><time datetime="2023-09-02T13:51:00.000Z" title="发表于 2023-09-02 21:51:00">2023-09-02</time></div></div><div class="aside-list-item"><a class="thumbnail" href="/posts/9a9b.html" title="Fedora-CoreOS配置与试用（2023年）"><img src="https://s1.ax1x.com/2023/08/28/pPa8tlF.png" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="Fedora-CoreOS配置与试用（2023年）"/></a><div class="content"><a class="title" href="/posts/9a9b.html" title="Fedora-CoreOS配置与试用（2023年）">Fedora-CoreOS配置与试用（2023年）</a><time datetime="2023-08-28T11:35:00.000Z" title="发表于 2023-08-28 19:35:00">2023-08-28</time></div></div></div></div></div></div></main><footer id="footer"><div id="footer-wrap"><div class="copyright">&copy;2019 - 2023 By MocusEZ</div><div class="framework-info"><span>框架 </span><a target="_blank" rel="noopener external nofollow noreferrer" href="https://hexo.io">Hexo</a><span class="footer-separator">|</span><span>主题 </span><a target="_blank" rel="noopener external nofollow noreferrer" href="https://github.com/jerryc127/hexo-theme-butterfly">Butterfly</a></div><div class="footer_custom_text"><a href="http://beian.miit.gov.cn/" rel="external nofollow noreferrer"  style="color:#f72b07" target="_blank">闽ICP备2021003009号</a></div></div></footer></div><div id="rightside"><div id="rightside-config-hide"><button id="readmode" type="button" title="阅读模式"><i class="fas fa-book-open"></i></button><button id="darkmode" type="button" title="浅色和深色模式转换"><i class="fas fa-adjust"></i></button><button id="hide-aside-btn" type="button" title="单栏和双栏切换"><i class="fas fa-arrows-alt-h"></i></button></div><div id="rightside-config-show"><button id="rightside_config" type="button" title="设置"><i class="fas fa-cog fa-spin"></i></button><button class="close" id="mobile-toc-button" type="button" title="目录"><i class="fas fa-list-ul"></i></button><a id="to_comment" href="#post-comment" title="直达评论"><i class="fas fa-comments"></i></a><button id="go-up" type="button" title="回到顶部"><i class="fas fa-arrow-up"></i></button></div></div><div id="local-search"><div class="search-dialog"><nav class="search-nav"><span class="search-dialog-title">搜索</span><span id="loading-status"></span><button class="search-close-button"><i class="fas fa-times"></i></button></nav><div class="is-center" id="loading-database"><i class="fas fa-spinner fa-pulse"></i><span>  数据库加载中</span></div><div class="search-wrap"><div id="local-search-input"><div class="local-search-box"><input class="local-search-box--input" placeholder="搜索文章" type="text"/></div></div><hr/><div id="local-search-results"></div></div></div><div id="search-mask"></div></div><div><script src="/js/utils.js"></script><script src="/js/main.js"></script><script src="https://cdn.jsdelivr.net/npm/@fancyapps/ui/dist/fancybox.umd.min.js"></script><script src="/js/search/local-search.js"></script><div class="js-pjax"><script>function loadWaline () {
  function insertCSS () {
    const link = document.createElement("link")
    link.rel = "stylesheet"
    link.href = "https://cdn.jsdelivr.net/npm/@waline/client/dist/waline.min.css"
    document.head.appendChild(link)
  }

  function initWaline () {
    const waline = Waline.init(Object.assign({
      el: '#waline-wrap',
      serverURL: 'https://waline.mocusez.site',
      pageview: ,
      dark: 'html[data-theme="dark"]',
      path: window.location.pathname,
      comment: false,
    }, null))
  }

  if (typeof Waline === 'function') initWaline()
  else {
    insertCSS()
    getScript('https://cdn.jsdelivr.net/npm/@waline/client/dist/waline.min.js').then(initWaline)
  }
}

if ('Waline' === 'Waline' || !false) {
  if (false) btf.loadComment(document.getElementById('waline-wrap'),loadWaline)
  else setTimeout(loadWaline, 0)
} else {
  function loadOtherComment () {
    loadWaline()
  }
}</script></div><script>(function(i,s,o,g,r,a,m){i["DaoVoiceObject"]=r;i[r]=i[r]||function(){(i[r].q=i[r].q||[]).push(arguments)},i[r].l=1*new Date();a=s.createElement(o),m=s.getElementsByTagName(o)[0];a.async=1;a.src=g;a.charset="utf-8";m.parentNode.insertBefore(a,m)})(window,document,"script",('https:' == document.location.protocol ? 'https:' : 'http:') + "//widget.daovoice.io/widget/1df8ba05.js","daovoice")
</script><script>var isChatBtn = false
daovoice('init', {
  app_id: '1df8ba05',},{
  launcher: { 
     disableLauncherIcon: isChatBtn // 悬浮 ICON 是否显示
  },
});
daovoice('update');

if (isChatBtn) {
  var chatBtnFn = () => {
    var chatBtn = document.getElementById("chat_btn")
    chatBtn.addEventListener("click", function(){
      daovoice('show')
    });
  }
  chatBtnFn()
} else {
  if (false) {
    function chatBtnHide () {
      daovoice('update', {},{
        launcher: { 
        disableLauncherIcon: true // 悬浮 ICON 是否显示
        },
      });
    }
    function chatBtnShow () {
      daovoice('update', {},{
        launcher: { 
        disableLauncherIcon: false // 悬浮 ICON 是否显示
        },
      });
    }
  }
}</script><script async data-pjax src="//busuanzi.ibruce.info/busuanzi/2.3/busuanzi.pure.mini.js"></script></div></body></html>